Anders Östling wrote:
> 
> 
> When an Outlook user sends an encrypted and signed message to a Netscape
> user,
> it crashes the outlook client when he attempt to read the message. The
> MS user can
> send the same message to himself w/o problems.
> 

I take it you mean that the Netscape client crashes?

There is a problem with all current Netscape clients. They misbehave
(usually crash) when they come across a certificate with a string type
they don't understand. This means a BMPString or a UTF8String. This
means that anything following the PKIX guidelines that uses certain
characters (international ones or things like '@' in certain fields)
will trigger this.

Signing a news group message with such a certificate could make you
rather unpopular...

This is a real pain and has been holding up things like proper
international character suppport in certificates.

Anyway apparently if you install Netscape personal security manager
(PSM) this problem doesn't seem to happen any more. At least it didn't
with a test certificate which crashed previous versions I'd tested it
on. I haven't had time to check this thoroughly yet though.

Steve.
-- 
Dr Stephen N. Henson.   http://www.drh-consultancy.demon.co.uk/
Personal Email: [EMAIL PROTECTED] 
Senior crypto engineer, Celo Communications: http://www.celocom.com/
Core developer of the   OpenSSL project: http://www.openssl.org/
Business Email: [EMAIL PROTECTED] PGP key: via homepage.

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to